California · Legislation Insight

SB354: California's Hidden Privacy Rules for Insurance Professionals

A California insurance privacy law contains strict new rules for small agencies—and most owners haven't heard about them yet.

Most California insurance producers and brokerages don't realize that SB354—the Insurance Information and Privacy Protection Act—contains a provision that will reshape how they handle customer data. And it takes effect July 1, 2028.

The provision, codified in Section 791.04(a)(1) under Article 6.6, imposes data-minimization and consent mandates on every licensed insurance licensee, regardless of size. That includes solo agents, small brokerages, and independent producers.

What the Law Requires

Starting July 1, 2028, you must:

Deliver a stand-alone privacy notice within 21 days. The first time you collect or access a consumer's personal information, you have 21 days to provide a compliant, written privacy notice. This is separate from any other disclosures you may already provide.

Renew the notice annually. You cannot issue a privacy notice once and assume compliance. You must deliver updated notices every year.

Get opt-in consent before sharing data. Before you share a consumer's information for marketing or research purposes, you must obtain their explicit, written consent. Opt-out is not enough; opt-in is required.

Document your retention practices. You must create and maintain written records-retention policies that spell out how long you keep consumer data and when you destroy it.

Lock down third-party contracts. Any service provider who handles consumer data on your behalf—whether a CRM vendor, email platform, or claims processor—must be bound by a compliant written contract that enforces the same privacy and data-handling standards you do.

Who This Affects

This is not limited to large insurers. The law applies to every licensed insurance producer and insurer in California. If you hold an insurance license and touch consumer data—even if you're a one-person shop—you are subject to these requirements.

Why It Matters Now

You have roughly three and a half years to prepare. That may sound like plenty of time, but building compliant processes, rewriting privacy notices, updating vendor contracts, and training staff takes planning. Waiting until 2027 or 2028 to start will create a compliance crunch.

Non-compliance carries risk. California's Department of Insurance has enforcement authority, and violations can result in fines, license discipline, or both.

Next Steps

Begin by auditing your current data practices: Where do you collect consumer information? How long do you keep it? Who has access? Which vendors touch your data? Then review your existing privacy notices and vendor agreements against the new standards outlined in Section 791.04(a)(1).

If you work with a compliance officer, broker association, or insurance attorney, now is the time to discuss how SB354 affects your specific business model and what changes you'll need to make.

This explainer is based on SB354, Section 791.04(a)(1), Article 6.6 (SEC. 2), operative July 1, 2028. For detailed guidance specific to your business, consult a California insurance compliance professional or your trade association.

Source: SB354 · Section 791.04(a)(1), Article 6.6 (SEC. 2) · Operative July 1, 2028 (Section 791.41); third-party service provider contracts must comply for agreements executed, ame · Legislative data via LegiScan (CC BY 4.0), read and summarized by RESignal. Awareness, not legal advice — verify at the source.
Want this for your own business?
Get a free, data-grounded read on professional services — the decisions, the money, and the rules that actually affect you, before you act.
Get my free brief →
© RESignal, Inc. · Patent Pending · All insights · Get a free brief